CVE-2006-5051
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 45.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 44.96% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-415
- Affected
- openbsd/openssh · debian/debian linux · apple/mac os x · apple/mac os x server
- Source
- secalert@redhat.com
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:22.openssh.ascBroken Link
- ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.ascBroken Link
- http://docs.info.apple.com/article.html?artnum=305214Broken Link
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlMailing List
- http://lists.freebsd.org/pipermail/freebsd-security/2006-October/004051.htmlMailing List
- http://marc.info/?l=openssh-unix-dev&m=115939141729160&w=2Mailing List
- http://openssh.org/txt/release-4.4Release Notes
- http://secunia.com/advisories/22158Broken Link, Vendor Advisory
- http://secunia.com/advisories/22173Broken Link, Vendor Advisory
- http://secunia.com/advisories/22183Broken Link, Vendor Advisory
- http://secunia.com/advisories/22196Broken Link, Vendor Advisory
- http://secunia.com/advisories/22208Broken Link, Vendor Advisory
- http://secunia.com/advisories/22236Broken Link, Vendor Advisory
- http://secunia.com/advisories/22245Broken Link, Vendor Advisory
- http://secunia.com/advisories/22270Broken Link, Vendor Advisory
- http://secunia.com/advisories/22352Broken Link, Vendor Advisory
- http://secunia.com/advisories/22362Broken Link, Vendor Advisory
- http://secunia.com/advisories/22487Broken Link, Vendor Advisory
- http://secunia.com/advisories/22495Broken Link
- http://secunia.com/advisories/22823Broken Link, Vendor Advisory
- http://secunia.com/advisories/22926Broken Link, Vendor Advisory
- http://secunia.com/advisories/23680Broken Link, Vendor Advisory
- http://secunia.com/advisories/24479Broken Link, Vendor Advisory
- http://secunia.com/advisories/24799Broken Link, Vendor Advisory
- http://secunia.com/advisories/24805Broken Link, Vendor Advisory
- http://security.freebsd.org/advisories/FreeBSD-SA-06%3A22.openssh.ascThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200611-06.xmlThird Party Advisory
- http://securitytracker.com/id?1016940Broken Link, Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.592566Broken Link
- http://sourceforge.net/forum/forum.php?forum_id=681763Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.